Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
yallaen
New Contributor

NTP sources

Hello all; New to Fortinet devices. I' m a Cisco network engineer that has transitioned to a firewall team. I have questions on using NTP with these Fortinet devices. 1. Can you use multiple sources for NTP? For example, I want my device to point to an internal GPS timeserver, with a back-up to an external known server. 2. Can you only set 1 source ip for both? Does it matter? I have an internal GPS unit that is on my internal network. I' m using ntpv3 and authentication to the internal device. However, it' s not synching. BUT, the external time server IS synching, and not using authentication. However, if I do a debug on the internal, I can see that it is authenticating correctly. I know on Cisco devices, you can use the " prefer" command to force it to use one NTP server..and only if it cannot connect will it try the others you specified. Thanks in advance!
3 REPLIES 3
emnoc
Esteemed Contributor III

1. Can you use multiple sources for NTP? For example, I want my device to point to an internal GPS timeserver, with a back-up to an external known server. 2. Can you only set 1 source ip for both? Does it matter?
on #1, you can have multiple NTP servers via the edit command under config ntpserver on #2 I don' t know of an option to specify the src interface Now on your problem, do you know for sure if your allowed in the NTP access list/group for the time server? I haven' t play with NTPv3 auth within fortios and most of the earlier device didn' t support authentication.

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
ede_pfau
Esteemed Contributor III

Chances are that NTP auth is only supported on FOS 5.0 (if at all). See the docs, esp " What' s new in 5.0" . Preference is given via the sequence of the NTP server addresses you specify. The first server can the entered via GUI or CLI, the second and third via CLI only. AFAIK the second and third servers are only queried if the first failed. As a Cisco man, you surely feel at home with the CLI, so no pointers here for the exact command (Saturday night on my couch at home...).

Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
bseklecki
New Contributor II

So: It has been almost a decade since the original post and I still don't see an option for designating a NTP preferred peer/server within the client config.  FYI my first post >:}

Labels
Top Kudoed Authors